VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3917 CVEsRSS

CVE-2025-66471High· 7.5
9mo ago

urllib3 is a user-friendly HTTP client library for Python

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large H…

▾ Twilightpython · urllib3EPSS 0.68%via NVD
CVE-2025-37727Medium· 5.7
11mo ago

Elasticsearch: Insertion of Sensitive Information into Log File via reindex API

Elasticsearch: Insertion of Sensitive Information into Log File via reindex API

▾ Sunlitelasticsearch · org.elasticsearch.plugin:reindex-clientEPSS 0.25%via GHSA
CVE-2025-9566High· 8.1
1y ago

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In…

▾ TwilightRed Hat · podmanEPSS 1.1%via NVD
CVE-2025-58048Critical· 9.9
1y ago

Paymenter is a free and open-source webshop solution for hostings

Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments functionality in Paymenter allows a malicious authenticated user to upload arbitrary files. This could result in sensitive…

▾ Midnightpaymenter · paymenter/paymenterEPSS 0.41%via NVD
CVE-2025-71348High· 8.1
1y ago

Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config

Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config

▾ Twilightpicklescan · picklescanEPSS 0.55%via OSV
CVE-2024-52980Medium· 6.5
1y ago

Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

▾ Sunlitelasticsearch · org.elasticsearch:elasticsearch-grokEPSS 0.54%via GHSA
CVE-2024-38819High· 7.5PoC
1y ago

Spring Framework Path Traversal vulnerability

Spring Framework Path Traversal vulnerability

▾ Midnightspringframework · org.springframework:spring-webfluxEPSS 56%via GHSA
CVE-2024-58351High
1y ago

Flowise OverrideConfig security vulnerability

Flowise OverrideConfig security vulnerability

▾ Twilightflowise · flowiseEPSS 0.93%via GHSA
CVE-2024-9355Medium· 6.5
1y ago

A vulnerability was found in Golang FIPS OpenSSL

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false posi…

▾ Sunlitgolang-fips · github.com/golang-fips/opensslEPSS 0.30%via NVD
CVE-2024-39896High· 7.5
2y ago

Directus Allows Single Sign-On User Enumeration

Directus Allows Single Sign-On User Enumeration

▾ Twilightdirectus · directusEPSS 0.51%via GHSA
CVE-2024-38355Medium· 7.3PoC
2y ago

socket.io has an unhandled 'error' event

socket.io has an unhandled 'error' event

▾ Twilightsocket.io · socket.ioEPSS 0.81%via GHSA
CVE-2023-41052Medium· 5.3
3y ago

incorrect order of evaluation of side effects for some builtins

incorrect order of evaluation of side effects for some builtins

▾ Sunlitvyper · vyperEPSS 0.54%via OSV
CVE-2022-39135Critical· 9.8
4y ago

Apache Calcite before 1.32.0 vulnerable to potential XML External Entity (XXE) attack

Apache Calcite before 1.32.0 vulnerable to potential XML External Entity (XXE) attack

▾ Midnightapache · org.apache.calcite:calcite-coreEPSS 2.2%via GHSA
CVE-2022-23064High· 8.8
4y ago

snipe-IT vulnerable to host header injection

snipe-IT vulnerable to host header injection

▾ Twilightsnipe · snipe/snipe-itEPSS 1.3%via GHSA
CVE-2022-0577Medium· 6.5
4y ago

Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapy

Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapy

▾ Sunlitscrapy · scrapyEPSS 1.3%via OSV
CVE-2020-10571Critical· 9.8
6y ago

Potential buffer overflow in psd-tools

Potential buffer overflow in psd-tools

▾ Midnightpsd-tools · psd-toolsEPSS 1.8%via OSV
CVE-2018-1000164High· 7.5
8y ago

Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers

Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers

▾ Twilightgunicorn · gunicornEPSS 2.4%via OSV
CVEs tagged “ghsa” — page 131 · VulnSea